Printer driver that encrypts print data
Abstract
A system for transmitting encrypted print job data across a network. The printer driver on the client device encrypts the print job data using a random AES key and uses the printer's public key to encrypt the random AES key. The print job data remains encrypted during transmission from the client device to the printer via the server. As such, the contents of the print job cannot be viewed by anyone who eavesdrops on the communications between the client device and the printer or by anyone who obtains the print job data from the server's data storage medium. The printer's public certificate, containing the printer's public key, is promulgated to the client device via the server which stores the printer's public certificate with other data pertinent to the client device's printer driver.
Claims
exact text as granted — not AI-modified1 . A system for securely transmitting an output device job, comprising:
an output device including an output device cryptographic module; a client device, the client device including a client output device driver having a client device cryptographic module; and a server operatively interposed between the client device and the output device on a network; wherein the output device cryptographic module is configured to generate a first key and to transmit the first key to the server, the server is configured to transmit the first key to the client device cryptographic module, the client device cryptographic module is configured to encrypt a first set of data using the first key, the client device is configured to transmit the encrypted first set of data to the output device cryptographic module via the server, and the output device cryptographic module is configured to decrypt the encrypted first set of data.
2 . The system of claim 1 , wherein the client device cryptographic module is configured to generate the first set of data comprising a second key, to encrypt a second set of data using the second key, and to transmit the encrypted second set of data to the output device cryptographic module via the server;
wherein the output device cryptographic module is configured to decrypt the encrypted second set of data using the second key; and wherein the first key is a public key of a public-private key pair and the second key is a symmetric key.
3 . The system of claim 2 , wherein the client device is configured to receive the client output device driver from the server via the network.
4 . The system of claim 3 , wherein the client device is configured to receive an updated client output device driver from the server via the network if the updated client output device driver is available on the server but has not yet been installed on the client device.
5 . The system of claim 4 , wherein the updated client output device driver includes an updated first key.
6 . The system of claim 1 , wherein the output device is a printer, the server is a print server, and the client output device driver is a printer driver.
7 . A client output device driver, comprising:
a rendering component; a client device cryptographic module operatively connected to receive data from the rendering component; and a user interface operatively connected to the client device cryptographic module.
8 . The client output device driver of claim 7 , wherein the client device cryptographic module comprises a key generator adapted to generate a symmetric key and a data encryption component adapted to encrypt data using the symmetric key and to encrypt the symmetric key using a public key.
9 . The output device driver of claim 7 , wherein the client output device driver is a printer driver.
10 . The client output device driver of claim 7 , wherein the client output device driver is installed on a client device and the client device is operatively connected to an output device via a network.
11 . The output device driver of claim 10 , wherein the output device includes an output device cryptographic module adapted to decrypt data encrypted by the client device cryptographic module.
12 . The output device driver of claim 11 , wherein the output device cryptographic module is configured to provide the public key to the client device cryptographic module via the network.
13 . A method of securely transmitting an output device job, comprising the steps of:
providing an output device, the output device including an output device cryptographic module; providing a client device, the client device including a client output device driver having a client device cryptographic module; providing a server, the server being operatively interposed between the client device and the output device on a network; generating a first key using the output device cryptographic module; transmitting the first key from the output device to the server via the network; transmitting the first key from the server to the client device; generating a second key on the client device cryptographic module; encrypting output data using the second key on the client device cryptographic module; encrypting the second key using the first key on the client device cryptographic module; transmitting the encrypted data and the encrypted second key from the client device to the output device cryptographic module via the server; decrypting the encrypted second key and the encrypted output data on the output device cryptographic module; and producing an output corresponding to the decrypted output data using the output device.
14 . The method of claim 13 , wherein the first key is a public key of a public-private key pair and the second key is a symmetric key.
15 . The method of claim 14 , wherein the step of providing a client device includes transmitting the client output device driver including the client device cryptographic module from the server to the client device.
16 . The method of claim 15 , further comprising the step of transmitting, from the server to the client device via the network, an updated client output device driver if the updated client output device driver is available on the server but has not yet been installed on the client device.
17 . The method of claim 16 , wherein the updated client output device driver includes an updated public key.
18 . The method of claim 13 , wherein the output device is a printer, the server is a print server, and the client output device driver is a printer driver.
19 . The method of claim 13 , further comprising the step of generating metadata corresponding to the output data.
20 . A method of securely transmitting data to a printer, comprising the steps of:
providing a client device, a server, and a printer operatively interconnected on a network; storing, on the server, a printer driver; transmitting a public key of the printer to the server; storing the public key of the printer on the server; transmitting from the server to the client device, upon request by the client device, the client printer driver; transmitting from the server to the client device, upon request by the client device, the public key of the printer; encrypting a print job on the client device using a symmetric key; encrypting the symmetric key on the client device using the public key; transmitting the encrypted print job and the encrypted symmetric key from the client device to the printer via the server; decrypting, on the printer, the encrypted symmetric key using a private key corresponding to the public key; decrypting the encrypted print job using the decrypted symmetric key; and printing output by the printer corresponding to the decrypted print job.
21 . The method of claim 20 , further comprising the steps of:
transmitting an updated public key from the printer to the server; storing the updated public key on the server; and transmitting, upon request by the client device, the updated public key from the server to the client device.
22 . The method of claim 21 , further comprising the step of generating the public key using the printer.
23 . The method of claim 22 , further comprising the step of generating the symmetric key using the client device.
24 . The method of claim 20 , further comprising the step of generating unencrypted metadata corresponding to the print job; wherein the metadata includes one or more of the group consisting of: job identification number, originating computer, job name, originating user, copies, pages, N-up, duplex, color, bytes printed, job time, queue, port name, host name, serial number, model, IP address, paper type, paper size, scan type, pages scanned, original media size, collated, destinations, MAC address, and data source.
25 . A system for securely transmitting an output device job, comprising:
an output device including an output device cryptographic module; a client device, the client device including a client device output device driver having a client device cryptographic module; and a server operatively interposed between the client device and the output device on a network; wherein the output device cryptographic module includes means for generating a first key and means for transmitting the first key to the server; the server includes means for transmitting the first key to the client device cryptographic module; the client device cryptographic module includes means for generating a second key, means for encrypting data using the second key, and means for encrypting the second key using the first key; the client device includes means for transmitting the encrypted data and the encrypted second key to the output device cryptographic module via the server; the output device cryptographic module includes means for decrypting the encrypted second key and the encrypted data; and the output device includes means for producing an output corresponding to the data.Join the waitlist — get patent alerts
Track US2009063860A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.